Fortinet Reports Surge in AI-Powered Cyber Attacks and Vulnerabilities
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
What Actually Happened
Fortinet, a leader in cybersecurity, released its 2025 Global Threat Landscape Report, indicating a dramatic increase in cyber threats driven by artificial intelligence and automation. In 2024, automated scanning activity surged by 16.7%, reaching 36,000 scans per second globally. The report, compiled by FortiGuard Labs, also noted that over 40,000 new vulnerabilities were added to the U.S. National Vulnerability Database, marking a 39% increase from the previous year.
Cybercriminals are increasingly targeting vulnerable digital assets earlier in the attack lifecycle, focusing on protocols like SIP, RDP, and systems such as IoT and operational technologies. The report highlights that infostealer malware has led to a staggering 500% increase in logs from compromised systems, with over 1.7 billion stolen credentials available on underground forums in 2024.
Why This Matters for Your Security
The rise of AI-powered phishing campaigns, using tools like FraudGPT and BlackmailerV3, has made it easier for attackers to create convincing content and evade detection. Manufacturing, business services, construction, and retail sectors are among the most targeted, with the United States experiencing 61% of all documented attacks.
Cloud vulnerabilities are also critical, with 70% of incidents linked to anomalous login locations. The report indicates that over 100 billion compromised records were shared on darknet forums in 2024, a 42% increase from the previous year, primarily through combo lists used in credential-stuffing attacks.
Fortinet emphasizes the need for organizations to adopt proactive, intelligence-driven cybersecurity strategies. The report includes a CISO Playbook for Adversary Defense, which outlines recommendations such as Continuous Threat Exposure Management, real-world attack simulations, and risk-based patch management.
Key Takeaways
- Implement Continuous Threat Exposure Management to monitor your attack surface in real-time.
- Conduct regular red/purple teaming exercises to test your defenses against real-world threats.
- Utilize Attack Surface Management tools to identify and mitigate vulnerabilities and leaked credentials.
- Prioritize patch management based on risk assessments using EPSS and CVSS scores.
- Integrate dark web intelligence to stay informed about emerging threats and potential breaches.
Key Terms & Concepts
- Infostealer: In this article, infostealer refers to malware that steals sensitive information, leading to significant data leaks.
- Ransomware-as-a-Service (RaaS): Ransomware-as-a-Service is a business model where cybercriminals offer ransomware tools and services to other criminals.
- Continuous Threat Exposure Management (CTEM): Continuous Threat Exposure Management is a proactive approach to cybersecurity that involves real-time monitoring and automated responses to threats.
- Dark Web Intelligence: Dark Web Intelligence refers to the monitoring of illicit online activities and data on the dark web to identify emerging threats.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.